Earlier quoted context omitted.
There's nothing wrong with offering a public API. There's everything wrong with offering a secret, non-public API where you give a third party I didn't consent to full access to all of my data. See how that's a bit different? One of them is offering public information (say, stock quotes), publicly. One of them is offering private information (my sexual orientation and date of birth) to tons of third parties I didn't…
Surely it is only giving blackberry the information if you type in your login credentials on a blackberry right? I don't see how the situation is actually different now: if you run the official Facebook app on your Galaxh phone then Samsung could scrape and exfiltrate the data anytime it wants. It is Samsung's fault if they do it not Facebook's.
Facebook officially blessed other platforms, allowed them to say you were signing into Facebook, and then allowed those platforms to have access not only to your data, but your friends exhaustive data. Facebook was aware of this, explicitly allowed this, and their only safeguard was vaguely worded policies with their partners.
Even if the partners haven't stolen any data or broken their policies, Facebook intentionally and knowingly gave my data to a third party without my consent. Presumably now all 66 of these device partners have my full data, and I did not sign in on their device or otherwise authorize it.